๐บ๐ธ
TPI-Abuse
2026-09-22 04:30:09
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.67.205.159 (159.205.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.67.205.159 (159.205.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:30:02.055430 2026] [security2:error] [pid 21233:tid 21233] [client 136.67.205.159:38516] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kruizekontrhl.com.darkalleyproductions.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kruizekontrhl.com.darkalleyproductions.com"] [uri "/.codex/auth.json.bak"] [unique_id "arIESgJ1FKwQewS_zJhi8QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 03:27:55
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.67.205.159 (159.205.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.67.205.159 (159.205.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 23:27:50.879291 2026] [security2:error] [pid 16545:tid 16556] [client 136.67.205.159:40442] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.koliosgroup.fevini.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.koliosgroup.fevini.com"] [uri "/.codex/auth.json.bak"] [unique_id "arH1trYTw0gnlOp4fMpeCAAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-22 00:36:04
(23 hours ago)
Bruteforce
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 20:56:44
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.67.205.159 (159.205.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.67.205.159 (159.205.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:56:36.317953 2026] [security2:error] [pid 4971:tid 4971] [client 136.67.205.159:39436] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.astglobaltech.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.astglobaltech.com"] [uri "/.codex/auth.json.bak"] [unique_id "arGaBAGpeN0NuYxNW5drUwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
febrian.de
2026-09-21 15:51:37
(1 day ago)
Excessive HTTP(S) probing or bad web bot detected by Fail2Ban
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 15:48:25
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
mnsf
2026-09-21 14:05:28
(1 day ago)
Too many Status 50X (41)
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-21 13:50:13
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 07:40:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
hbrks
2026-09-21 06:56:52
(1 day ago)
42 attack(s) detected, such as these: {"event":"web_block","ip":"136.67.205.159","host":"pptr.marche ...
show more
42 attack(s) detected, such as these: {"event":"web_block","ip":"136.67.205.159","host":"pptr.marche-be.com","request":"GET /tmp/.codex/auth.json HTTP/1.1","user_agent":"","reason":"Status-301","timestamp":"2026-09-21T06:56:52 00:00","logentry":"pptr.marche-be.com 136.67.205.159 - - [21/Sep/2026:06:56:52 0000] \"GET /tmp/.codex/auth.json HTTP/1.1\" 301 169 \"-\" \"crusader-worker/1.0\" \"-\""} * Report Details *: https://p4u.xyz/OLX7FIHSDSV/1* IP Details *: https://p4u.xyz/OLX7FIHSDSV/2
show less
Web Spam
Hacking
Bad Web Bot
๐ณ๐ด
jad-abuse
2026-09-21 06:26:03
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_u ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_ua, ai_secrets. Observed by 1 sensor(s); 41 hits.
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 04:18:25
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
Uwe Sarpe
2026-09-21 04:08:03
(1 day ago)
[Mon Sep 21 06:08:02.745235 2026] [access_compat:error] [pid 523250:tid 523250] [client 136.67.205.1 ...
show more
[Mon Sep 21 06:08:02.745235 2026] [access_compat:error] [pid 523250:tid 523250] [client 136.67.205.159:60432] AH01797: client denied by server configuration: /var/www/wwwroot
[Mon Sep 21 06:08:02.752214 2026] [access_compat:error] [pid 516557:tid 516557] [client 136.67.205.159:60348] AH01797: client denied by server configuration: /var/www/config
[Mon Sep 21 06:08:02.755373 2026] [access_compat:error] [pid 521971:tid 521971] [client 136.67.205.159:60242] AH01797: client denied by server configuration: /var/www/bak
[Mon Sep 21 06:08:02.756727 2026] [access_compat:error] [pid 515984:tid 515984] [client 136.67.205.159:60458] AH01797: client denied by server configuration: /var/www/.claude
[Mon Sep 21 06:08:02.760244 2026] [access_compat:error] [pid 523251:tid 523251] [client 136.67.205.159:60304] AH01797: client denied by server configuration: /var/www/.claude
...
show less
Brute-Force
Web App Attack